As more digital systems are deployed, IT product security is now a critical concern within the government, defence, finance, healthcare, and even commercial systems. The difference in security design and implementation may cause vulnerability unless it is correctly evaluated. IEC 15408 offers a formal and standardized framework for defining security goals, defining threats, and determining whether IT products are sufficient to cope with the threats. The standard allows a clear assessment of security, global confidence, and confidence in certified IT products.
Get Certified IEC 15408 for Trusted IT Security
The IEC 15408 certification shows that an IT product or system has been evaluated with respect to security in a strict, independent manner. Certification improves market acceptance, regulatory needs, and procurement needs, as well as the user confidence in the product security. Adherence to IEC 15408 is generally mandatory in government and high-security installations and supports cross-border acceptance by providing Common Criteria recognition agreements.
IEC 15408 Requirements and Evaluation Criteria
| Security Assurance Requirements (SARs) | Security measures that guarantee the proper execution of security functions. |
| Protection Profiles (PPs) | There are standard security requirements for a given product type. |
| Security Targets (STs) | Product-specific security claims and implementation details |
| Evaluation Assurance Levels (EALs) | Graded levels of evaluation depth and rigor |
| Vulnerability Analysis | Assessment of resistance to known and potential attacks |
| Documentation | Comprehensive security and design documentation |
